Organisations often have more assurance activity than they realise and less assurance than they think. One control may be reviewed by the business, compliance, risk and audit, while another material control is supported only by an annual self-attestation.
Practical situation: A group reports “full assurance” over a critical process because four reviews were completed. All four relied on the same management evidence and none tested the automated interface causing repeated incidents. Volume of assurance obscured the common blind spot.
Combined assurance should map material risks and controls to the source, scope, timing, independence and conclusion of assurance. The aim is not to merge all providers, but to understand confidence, overlap, gaps and unresolved findings.
Why this belongs on the ERM agenda now#
Assurance providers use different scopes and ratings#
Management testing, compliance review, risk challenge, internal audit and external assurance cannot be counted as interchangeable checks. That matters because traditional controls often react after the exposure has already moved. The ERM response should therefore define an owner, a decision trigger and evidence showing whether the organisation’s approach to combined assurance framework is improving or deteriorating.
Duplication creates fatigue and cost#
Business teams may provide the same evidence repeatedly while receiving little additional insight. The practical consequence is easy to miss. A useful response converts the concern into observable signals, named decisions and time-bound actions rather than adding another narrative risk to the register.
Coverage gaps hide behind activity counts#
A risk can have many reviews that miss one critical control, entity, period or failure mode. This changes the risk conversation in a very concrete way. Management should be able to see what would trigger escalation, who can act and how quickly the organisation can change course.
What good looks like#
The test of combined assurance framework is not whether the methodology looks complete on paper. It is whether first-line teams can use it under normal operating pressure and whether challenge functions can trace the conclusion without rebuilding the facts. Proportionate governance is essential: material decisions receive independent review and stronger evidence, while routine activity follows simpler rules. One core feature is: Material risks and key controls are mapped to assurance sources and periods.
In practice, a credible target state includes:
-
Material risks and key controls are mapped to assurance sources and periods.
-
Assurance strength reflects scope, method, evidence and independence.
-
Duplicate requests are coordinated or reused where reliance is justified.
-
Gaps, conflicting conclusions and stale coverage are visible.
-
Open findings and remediation affect the assurance conclusion.
A practical combined-assurance model#
1. Define the assurance universe#
The strongest programmes begin with a narrow, testable definition. Start with material risks, critical services and key controls. Avoid mapping every low-risk control before the enterprise priorities are clear.
The decision file should retain risk or service, control, owner, materiality, required assurance and decision forum. That evidence keeps the judgement on combined assurance framework traceable when ownership, assumptions or operating conditions change.
2. Inventory assurance activity#
This is where ownership becomes visible. Capture management checks, second-line reviews, compliance monitoring, internal audit, external audit, certification, regulator review and specialist testing.
Minimum evidence should include provider, scope, period, method, evidence, independence, conclusion, findings and next review. The result should be reusable in monitoring and reporting, not a one-off document that disappears after the Inventory assurance activity step is complete.
3. Assess assurance strength#
Design the step around the exception that management would need to understand quickly. Evaluate whether the work covered the relevant entity, control, period and failure modes, and whether evidence was independently tested. Use transparent criteria rather than provider labels alone.
A reviewer should be able to find strength rating, rationale, limitation, reliance decision, reviewer and expiry. This allows challenge to focus on the quality of the decision rather than on reconstructing the history of combined assurance framework.
4. Map overlap and gaps#
Start by making the decision explicit. Compare planned and completed assurance against material risk and control needs. Identify repeated evidence requests, missing controls, stale reviews and conflicting conclusions.
The practical output is coverage status, overlap, gap, conflict, affected exposure, owner and action. Clear evidence also makes it easier to distinguish a genuine change in combined assurance framework from a change in wording or presentation.
5. Coordinate plans and evidence#
Keep this step deliberately simple. Align annual assurance calendars, share approved evidence and sequence work where appropriate. Preserve independence by allowing each provider to determine scope and conclusion.
Do not close the step without plan, timing, evidence source, reliance boundary, hand-off and approval. The record should enable another qualified person to understand the decision, test it and continue the work without relying on personal memory.
6. Report confidence and remediation#
Treat this as an operating requirement, not a documentation exercise. Show the Board and management where assurance is strong, partial or absent and how open findings affect confidence. Track gap closure and repeat issues.
The control record should show assurance map, finding severity, remediation, expected coverage, owner and review date. Recording those elements shows how the Report confidence and remediation step supports the wider approach to combined assurance framework and gives the next reviewer a usable starting point.
Ownership and decision rights#
Effective governance of combined assurance framework requires more than a name in the risk register. The operating chain should connect the business decision, the controls and data used to support it, independent challenge and the forum that can accept or change the exposure. Five responsibilities deserve explicit treatment.
- Executive sponsor: owns the outcome and approves trade-offs that exceed a function’s authority. The sponsor should understand how combined assurance framework affects the wider Board and Assurance agenda and what delay would mean for customers, services, strategy or legal entities.
- First-line owner: runs the activity that creates or manages the exposure. This person should lead the work to define the assurance universe, keep the conclusion current and translate it into operating choices.
- Control and data owners: operate the controls and produce the evidence behind measures such as Material risks with adequate current assurance. For combined assurance framework, they should explain lineage, exceptions, manual intervention and the response when a control or feed fails.
- Second-line challenge: tests scope, assumptions, rating, appetite interpretation and proposed action. It should challenge the risk of counting assurance activities, document disagreement and confirm when higher authority is required.
- Assurance and governance forums: assess whether the process works in practice and whether material conclusions reach the right committee. They should test whether the organisation can report confidence and remediation, whether open weaknesses are visible and whether prior decisions produced the expected result.
For combined assurance framework, a responsibility matrix is only the beginning. The workflow should preserve who submitted, reviewed, challenged, approved, changed and closed each material record, together with the date and rationale. That history protects continuity when teams, suppliers or legal-entity leadership change.
A realistic maturity path#
The practical way to strengthen combined assurance framework is to move from visibility, to connected control, to anticipation. Skipping the first two levels usually creates sophisticated reporting on unreliable foundations.
Level 1: establish visibility#
Define the minimum viable record for combined assurance framework, including scope, owner, rating or status, evidence and review date. Reporting Material risks with adequate current assurance should expose where the basic control environment is incomplete.
Level 2: connect decisions and controls#
Connect the combined assurance framework record to controls, indicators, incidents, obligations and actions. Introduce review workflow and trend reporting, using Key controls relying only on self-attestation and Duplicate evidence requests to direct meetings toward exceptions and decisions.
Level 3: anticipate and optimise#
Add predictive and scenario-based insight only after the underlying records for combined assurance framework are trusted. Assurance map linking risks, controls, providers, scope, period and conclusions can then help management compare options, concentrations and lead times rather than simply automate a static score.
Additional sophistication is justified only when it improves the quality or speed of decisions about combined assurance framework.
Measures that are useful in management meetings#
Do not measure combined assurance framework simply because data is available. Begin with Material risks with adequate current assurance and ask what decision the measure supports, which threshold matters and who acts when the trend changes. Pairing counts with exposure and service impact prevents false reassurance from a tidy percentage.
-
Material risks with adequate current assurance: Measures priority coverage.
-
Key controls relying only on self-attestation: Shows weak confidence.
-
Duplicate evidence requests: Measures coordination opportunity.
-
Assurance gaps overdue by risk severity: Tracks unresolved exposure.
-
Conflicting conclusions without resolution: Reveals uncertainty.
-
Repeat findings after prior assurance: Tests effectiveness.
Common failure modes#
-
Counting assurance activities: Quantity does not show scope or quality.
-
Treating all assurance as equivalent: Independence and testing depth differ.
-
Using the map to restrict audit independence: Coordination should not predetermine conclusion.
-
Ignoring open findings: Coverage can exist while confidence remains low.
-
Mapping every control before material risks: The exercise becomes too large to complete or use.
A 90-day implementation plan#
Days 1–30: establish the facts#
Select the top ten enterprise risks and key controls. Inventory current and planned assurance, including management testing, compliance, risk, audit and external work. Identify obvious overlap, gaps and stale conclusions.
Days 31–60: test the operating model#
Agree assurance-strength criteria and pilot a map for two risks. Coordinate evidence and timing, resolve one conflicting conclusion and create actions for material gaps without limiting provider independence.
Days 61–90: embed the management rhythm#
Approve combined-assurance governance and reporting. Integrate annual plans, findings and remediation, and present a concise coverage and confidence view to the relevant committee or Board.
How technology should support the process#
Technology should make combined assurance framework easier to coordinate and harder to lose in email or disconnected spreadsheets. It should expose ownership, evidence, approvals, exceptions and changes without hiding judgement behind a score. One useful starting capability is Assurance map linking risks, controls, providers, scope, period and conclusions. The broader requirement set is:
-
Assurance map linking risks, controls, providers, scope, period and conclusions.
-
Risk-based audit, compliance and control-testing plans.
-
Evidence reuse with clear reliance and independence boundaries.
-
Findings, issues, remediation and repeat-observation tracking.
-
Board dashboards for full, partial, stale and missing assurance coverage.
For combined assurance framework, the closest Vilfora product workspace is /regquanta/internal-audit/assurance-map. A useful implementation should connect that workspace to the relevant risks, controls, obligations, incidents, actions and reports rather than treating it as an isolated register.
Global implementation lens#
International implementation of combined assurance framework should distinguish the enterprise minimum from the local overlay. The group can standardise materiality and decision rights, while legal entities document the jurisdiction, language, market structure and delegated authority that change how the control operates.
For this topic, common records should support assurance coverage and confidence without forcing local teams to hide legitimate differences. The global view should report Material risks with adequate current assurance consistently, preserve the source evidence and show where data or terminology cannot be aggregated safely.
Local governance should then specify who will define the assurance universe, which forum owns exceptions and how issues involving follow-up and source traceability are escalated. This produces comparable governance across countries without turning the global framework into identical paperwork everywhere.
Questions senior management should ask#
-
Which material risks lack current independent assurance?
-
Where do several providers test the same evidence but miss the same control?
-
What conclusion depends only on management attestation?
-
Which conflicting assurance results remain unresolved?
-
How do open findings change the stated level of confidence?
Frequently asked questions#
What is combined assurance?#
It is a coordinated view of assurance from management, risk, compliance, internal audit, external providers and other sources across material risks and controls.
Does combined assurance merge the three lines?#
No. It improves coordination and visibility while preserving the roles, accountability and independence of each assurance provider.
How should assurance strength be rated?#
Consider scope, period, method, evidence, independence, limitations and findings. A transparent criterion is more useful than rating by provider name alone.
Where should implementation start?#
Begin with top enterprise risks, critical services and key controls. Expand after the mapping method and management use are proven.
Final takeaway#
Combined assurance adds value when it turns a collection of reviews into a clear answer about where management can rely on controls—and where it cannot. A workable ERM process creates enough structure to act under uncertainty: it identifies the signal, makes the trade-off explicit and tracks whether the response reduced exposure. Apply that discipline to combined assurance framework.
For organisations assessing an ERM platform, /regquanta/internal-audit/assurance-map should not stand alone. In Vilfora ERM, the value comes from linking combined assurance framework to evidence, incidents, obligations, remediation and Board reporting so that every material conclusion remains traceable.




